Impact
Payload CMS, an open‑source headless content‑management system, has an authorization bypass that occurs when querying a readable collection that contains a relationship to another collection. The query can expose information about related documents protected by an access.read constraint, allowing an attacker to read data they should not have access to. This flaw is an example of missing or inadequate access control, as identified by CWE‑862.
Affected Systems
Organizations using Payload CMS should review the affected versions. The vulnerability exists in all releases prior to 3.90.0, as well as all canary builds before 4.0.0‑canary.34. The fix was delivered in Payload CMS 3.90.0 and 4.0.0‑canary.34 and later.
Risk and Exploitability
The CVSS score is 6.9, indicating a moderate level of severity. No EPSS data is available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is a standard API request to the collection endpoint; an attacker who can read the source collection can retrieve data from related collections that are otherwise restricted. Successful exploitation would lead to unauthorized disclosure of protected documents, but it does not allow execution, modification, or denial of service.
OpenCVE Enrichment
Github GHSA